Case Library / Smishing (SMS Phishing) / Microsoft LAPSUS$ / DEV-0537 Source-Code Intrusion (2022)

Microsoft LAPSUS$ / DEV-0537 Source-Code Intrusion (2022)

A single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository, from which the group exfiltrated and publicly leaked roughly 37GB of partial source code for Bing, Bing Maps, and Cortana in March 2022, part of a wider spree in which the group used MFA push-bombing, SIM swaps, and paid-for insider MFA approvals to breach well-defended tech companies.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Over the weekend of March 19-21, 2022, the LAPSUS$ extortion group (Microsoft-tracked as DEV-0537) publicly claimed to have breached Microsoft, first posting screenshots of what appeared to be internal Azure DevOps source-code repositories, then on the night of March 21 posting a torrent for a ~9GB compressed (37GB uncompressed) 7zip archive containing partial source code for over 250 internal projects, including Bing, Bing Maps, and Cortana. On the evening of March 22, 2022, Microsoft published a blog post ("DEV-0537 criminal actor targeting organizations for data exfiltration and destruction") confirming that a single employee account had been compromised, giving the group "limited access" that was used to exfiltrate portions of source code; Microsoft stated no customer code or data was involved. Microsoft's security team said it had already been investigating the compromised account based on threat intelligence before the actor's public disclosure, and that the disclosure let the team escalate its response and interrupt the actor "mid-operation." Microsoft did not disclose exactly how the specific employee account was compromised, but framed the intrusion as consistent with DEV-0537's broader documented playbook. DEV-0537 is a group that, across its 2021-2022 campaign against dozens of organizations (including Okta, Nvidia, Samsung, T-Mobile, Ubisoft, Vodafone, and Globant), relied on MFA push-bombing/fatigue, SIM swapping to hijack SMS/voice MFA, buying credentials and session tokens from criminal marketplaces, and directly paying employees, suppliers, or business partners of target organizations for network credentials and MFA approval. Two days later, on March 24, 2022, City of London Police announced the arrest of seven people aged 16-21 in connection with the LAPSUS$ investigation (one trade outlet, Computer Weekly, separately reports the arrests themselves took place March 25); researchers and the BBC identified a 16-year-old from Oxford, England (alias "White"/"Breachbase," later named as Arion Kurtaj) as an alleged ringleader who had amassed roughly $14M in Bitcoin. Two teenagers were formally charged on April 1, 2022. In August 2023, the US Cyber Safety Review Board (CISA) published a dedicated government report on LAPSUS$ documenting the group's MFA-fatigue and SIM-swap techniques in detail and citing the Microsoft compromise as an exemplar case.

How the Attack Worked

Microsoft's blog did not disclose the specific initial-access technique used against its own compromised employee account, but described it as reflecting DEV-0537/LAPSUS$'s standard TTP playbook, later corroborated in detail by CISA's Cyber Safety Review Board (CSRB) report. At a general/awareness level, the group's methods were: (1) obtaining an initial foothold via purchased credentials/session tokens from criminal forums, Redline info-stealer harvests, exposed secrets in public code repos, or by directly paying an employee/contractor/supplier for login access; (2) where SMS/voice MFA protected an account, performing a SIM swap (social-engineering or bribing telecom staff/using compromised telecom employee accounts to reassign the victim's number to an attacker-controlled SIM) to intercept one-time codes; (3) where push-based MFA was in use, "MFA fatigue"/push-bombing: repeatedly triggering approval prompts (often at inconvenient hours) until the target approved one out of annoyance, or paying/soliciting an insider to simply approve the prompt themselves; (4) in some incidents, calling the target's help desk while impersonating the employee (using previously gathered personal details/profile photos and a native-English-sounding caller) to talk support staff into resetting credentials or MFA enrollment outright. Once inside, DEV-0537 used tools like AD Explorer to map privileged accounts, pivoted through Slack/Teams/Jira/Confluence to harvest further credentials, exploited known vulnerabilities in on-prem Jira/GitLab/Confluence servers, and exfiltrated data via NordVPN egress points geographically close to the victim to blend in. For Microsoft specifically, the actor reached an Azure DevOps source-code repository through the single compromised account.

The Lure & the Tell

There was no phishing email or deceptive message to the victim organization in the traditional sense. The "lure" operated on Microsoft's employee and/or the identity infrastructure protecting their account. Tell-tale signs the CSRB later flagged as detectable indicators across LAPSUS$ incidents generally: a sudden burst of MFA push notifications, especially clustered at odd hours (e.g., 1am) designed to wear the user down into approving one out of fatigue; help-desk contacts requesting password/MFA resets where the caller could not be verified through an out-of-band channel; and unexplained SIM/number-reassignment notifications from a carrier. LAPSUS$ itself was unusually loud afterward: it publicly announced the Microsoft compromise on its own Telegram channel and torrented a 9GB (37GB uncompressed) archive of source code before Microsoft's confirmation, which is atypical for financially motivated intrusion actors and was itself the tell that first surfaced the breach publicly.

Outcome

Microsoft's security team, which was already investigating the compromised account on threat-intelligence leads before LAPSUS$'s public disclosure, used that disclosure to accelerate remediation: the account was locked down/remediated and the intrusion interrupted "mid-operation." Microsoft stated no customer code or data was affected and downplayed the severity, noting it does not rely on source-code secrecy as a security control. Separately, City of London Police announced the arrest of seven people aged 16-21 on 2022-03-24 in connection with the LAPSUS$ investigation (Computer Weekly separately reports the arrests themselves took place 2022-03-25); two teenagers (16 and 17) were charged on 2022-04-01 under the UK Computer Misuse Act and fraud statutes. The alleged ringleader, later publicly identified as Arion Kurtaj (Oxford, autistic, deemed unfit to stand trial), continued hacking while on bail (Uber, Revolut, Rockstar Games in Sept 2022); a Southwark Crown Court jury found on 2023-08-23, in a "trial of the facts" (not a conviction, given his unfitness to stand trial), that he had committed those acts, and he was sentenced 2023-12-21 to an indefinite hospital order. A 17-year-old co-defendant was convicted (an actual conviction) for related hacks of Nvidia and BT/EE. These later findings relate to Kurtaj's broader LAPSUS$-linked spree, not specifically adjudicated as the Microsoft intrusion. In August 2023, the US CISA Cyber Safety Review Board published a dedicated review of LAPSUS$ tactics (citing the Microsoft incident) with ecosystem-wide recommendations on passwordless authentication and SIM-swap controls.

Why It Matters

This intrusion demonstrated, at a company with world-class security engineering, that identity is the new perimeter and that MFA is not a monolithic control: SMS/voice-based MFA can be defeated wholesale via SIM swapping, and even app-based push MFA can be worn down by sheer repetition (push-bombing) or simply purchased from a bribed insider. A single compromised employee account was sufficient to reach a source-code repository, illustrating how identity compromise, not sophisticated malware or zero-days, was the common thread across LAPSUS$'s breaches of Microsoft, Okta, Nvidia, Samsung, and others. It also showed that a threat actor's operational carelessness (LAPSUS$'s public bragging and poor OPSEC) can be what first surfaces and accelerates response to an otherwise-quiet intrusion, and that some of the most damaging intrusions against Fortune 500 identity/security ecosystems can be carried out by unsophisticated, teenage, loosely organized actors rather than nation-states, prompting the US government's first CSRB deep-dive into a purely criminal (non-nation-state) actor.

Defenses

CISA's Cyber Safety Review Board (CSRB), in its July 24/Aug 10 2023 report on LAPSUS$, recommended: eliminating SMS- and voice-call-based MFA in favor of FIDO2-compliant phishing-resistant/passwordless authentication (number-matching push MFA is still vulnerable to fatigue attacks; hardware keys/passkeys are not); requiring explicit step-up authentication for sensitive actions rather than one-time login MFA; strict identity verification for help-desk password/MFA resets (out-of-band verification, callback to a pre-registered number, supervisor sign-off); telecom-side SIM-swap protections (account locks, strong ID verification, customer alerts) and FCC/FTC oversight of carriers; monitoring for anomalous MFA-prompt volume/timing (e.g., prompts at 1am) as a detection signal; segmenting/limiting source-code repository access and monitoring Azure DevOps/GitHub/GitLab for unusual access patterns; and organizational security-culture measures so employees report suspicious MFA prompts or bribery solicitations instead of acting on them. Microsoft's own blog echoed several of these (strong MFA, no SMS/voice MFA, employee education on social engineering, help-desk verification processes).

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and target profiling: DEV-0537/LAPSUS$ is documented, per Microsoft's blog and the CISA CSRB report, as researching target organizations' employees, team structures, help-desk workflows, and supply-chain relationships before initial contact, likely drawing on LinkedIn, other OSINT sources, and previously breached personal data to build convincing profiles of real staff.
Countering Stage 1: Employee-facing OSINT exposure (org charts, LinkedIn, help-desk workflows) is very hard to eliminate at enterprise scale; the realistic control assumes attackers already have this profile information and hardens the identity and help-desk processes it gets used against, rather than trying to suppress the exposure itself.
2
Credential acquisition: The group typically obtained initial account access through multiple parallel channels: deploying commodity information-stealer malware (Redline) to harvest saved passwords and session tokens, purchasing credentials and session tokens from criminal underground marketplaces, scanning public code repositories for exposed secrets, and directly soliciting or paying employees, contractors, or suppliers, often via Telegram, for their login credentials.
Countering Stage 2: Monitor for credentials exposed in breach dumps or public repos and rotate them quickly, deploy endpoint detection tuned to info-stealer malware families like Redline, and run insider-risk/anti-bribery awareness programs so employees recognize and report solicitation attempts instead of acting on them.
3
MFA-circumvention setup: Where an account was protected by SMS or voice-based one-time codes, the group performed or arranged SIM-swap attacks (via telecom-employee bribery or telecom-side social engineering) to reroute the victim's phone number to an attacker-controlled device, and separately cultivated insiders willing to approve MFA prompts directly.
Countering Stage 3: Eliminate SMS/voice-based MFA in favor of FIDO2-compliant hardware keys or passkeys, which are not vulnerable to SIM-swap interception, and require telecom-side protections (account locks, strong ID verification, customer alerts) so number-porting cannot be socially engineered.
4
Initial access and MFA fatigue: With valid or purchased credentials in hand, the group logged in to internet-facing systems (VPNs, virtual desktop infrastructure, identity providers) and, where push-based MFA blocked them, repeatedly triggered approval prompts, often at inconvenient hours, until the legitimate user approved one out of fatigue or a recruited insider approved it directly.
Countering Stage 4: Replace simple push-approval MFA with number-matching or phishing-resistant authentication, cap how many prompts a single login attempt can generate, and monitor for anomalous prompt volume or timing (such as a burst of requests at 1am) as an active detection signal.
5
Help-desk social engineering (used in some incidents): The group called the target's help desk, impersonating the employee using previously gathered personal details and profile photos, with a native-English-sounding caller, to convince support staff to reset the account's password or MFA enrollment outright.
Countering Stage 5: Require strict, verifiable identity checks for any help-desk password/MFA reset, such as callback to a pre-registered number, supervisor sign-off, or in-person verification, so a caller with only stolen personal details cannot talk staff into a reset.
6
Internal reconnaissance and privilege escalation: Once inside, the group used publicly available tools such as AD Explorer to map privileged accounts and pivoted through internal collaboration platforms (Slack, Teams, Jira, Confluence) to harvest further credentials, in some cases exploiting known vulnerabilities in on-premises Jira, GitLab, or Confluence servers.
Countering Stage 6: Limit standing privileged-account visibility (restrict who can run directory-enumeration tools like AD Explorer), patch known vulnerabilities in on-premises Jira/GitLab/Confluence promptly, and monitor collaboration platforms for unusual credential-harvesting activity.
7
Lateral movement to the target repository: The compromised credentials/session were used to reach source-code and development infrastructure, in Microsoft's case a single Azure DevOps repository holding partial source for Bing, Bing Maps, and Cortana.
Countering Stage 7: Segment and tightly scope access to source-code repositories, apply least-privilege so a single compromised account cannot reach broad swaths of code, and monitor Azure DevOps/GitHub/GitLab for anomalous access patterns, consistent with the CSRB's own recommendation.
8
Exfiltration: Data was moved out over consumer VPN services (NordVPN), routed through egress points geographically close to the victim to avoid triggering location-based anomaly detection.
Countering Stage 8: Monitor egress traffic for connections to consumer VPN exit nodes and flag large or unusual data transfers, even when the destination IP geolocates near the victim.
9
Public leak and extortion/notoriety payoff: Rather than deploying ransomware, the group completed its objective by publicly posting screenshots, then torrenting the stolen archive and announcing the breach on its own Telegram channel, converting the intrusion into public notoriety and extortion leverage without ever demanding a ransom payment from Microsoft specifically.
Countering Stage 9: There is no technical control that prevents an attacker from choosing to publicize data it has already exfiltrated; the realistic mitigation sits upstream, at Stages 3 through 7 (phishing-resistant MFA, help-desk verification, and repository segmentation), since once the archive is out, the remaining response is limited to fast confirmation, transparency, and remediation of the kind Microsoft actually carried out.
Quick Facts
Victim
Microsoft Corporation
Location
Victim: Redmond, Washington, USA. Threat actor: primarily UK-based (Oxford, England) with additional members reportedly in Brazil/South America; investigation led by City of London Police with NCA support.
Date
2022-03-22 (Microsoft blog confirmation; source-code leak surfaced 2022-03-20/21; UK arrests announced 2022-03-24, though Computer Weekly separately reports the actual arrests occurred 2022-03-25)
Impact
Not publicly quantified by Microsoft. Microsoft characterized the exposure as low-severity, stating source-code secrecy is not a security control and that "viewing source code does not lead to elevation of risk"; no customer code or data was affected, and no dollar loss figure has ever been disclosed for the Microsoft intrusion specifically. (For scale/context only, not part of the Microsoft loss. These are unrelated victims, not Microsoft: BBC, Dec 2023, reported that LAPSUS$ member Arion Kurtaj's separate 2022 hacks of Uber, Nvidia, and Rockstar Games together cost the three firms combined "nearly $10m," not $10M as a third figure alongside individual per-company totals. Individual figures are inconsistent across outlets: Reuters/BBC cite roughly $3M in Uber damage; BBC separately says the Rockstar hack "cost it $5m to recover from," while Sky News instead attributes a $5m remedial-cost figure to Nvidia and gives Rockstar only $1.5m "in external help alone" plus unquantified marketing-related losses. Outlets do not agree on which company the $5M figure belongs to, and this record does not attempt to resolve that discrepancy.)
Status
Confirmed
Case Type
Real-World Incident
Sector
Technology & Software
Threat Actor
Organized Crime
Related

Related Cases

Caesars Entertainment Vendor Social Engineering Breach (2023)

Attackers later attributed to Scattered Spider (a group representative initially denied involvement) social-engineered Caesars Entertainment's outsourced IT support vendor, since…

Incident 2023Read →

EA Games Slack/MFA Social Engineering Breach (2021)

Hackers bought a $10 stolen Slack session cookie, used it to reach EA's internal Slack, then twice talked EA IT…

Incident 2021Read →

Uber 2022 Breach: MFA Push-Bombing and IT-Support Impersonation of a Contractor

A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…

Incident 2022Read →